CVE-2024-20728

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Feb 15, 2024
Updated: Mar 1, 2024
CWE ID 787

Summary

CVE-2024-20728 is a newly disclosed vulnerability affecting Acrobat Reader versions 20.005.30539 and 23.008.20470, and possibly older releases. This issue constitutes an out-of-bounds write vulnerability, which allows malicious code execution in the context of the current user. For an attack to be successful, the victim must open a specially crafted file. Successful exploitation could lead to significant security risks. Users are urged to update their Acrobat Reader software to the latest version as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Adobe Acrobat DC
  • Adobe Acrobat Reader
  • Adobe Acrobat
  • Adobe Acrobat Reader DC

Affected Vendors

  • Adobe